Trust

Security and data

The short version: tools connect through their own sign-in, tokens are encrypted, your data is yours alone, and every change Sands makes is recorded.

Connections and credentials

  • Every tool connects through its own sign-in (OAuth). Sands never sees your passwords.
  • Tokens are stored encrypted and tied to your account. Sands works with the access you granted, nothing wider.
  • Disconnect from Settings at any time, or revoke access from the tool's own settings.

Your data

  • Chats, plans, uploads and settings belong to your account. The database enforces that no other account can read them.
  • Uploaded files are stored privately; only you can open them.
  • Every run keeps its record: what Sands read, what it changed, and what you approved.
  • Deleting your account deletes your data and disconnects your tools.

Changes to your tools

  • Sands only carries out changes you asked for, on items it can identify.
  • Your approval mode decides when Sands asks first. Riskier changes pause by default.
  • An approved change runs exactly as approved. If the target or content changed since, it does not run.
  • Each change runs once and is read back after it runs.

See Approvals and How Sands works.

Compliance

Sands runs on SOC 2 certified infrastructure; our own SOC 2 program is underway. Ask for current status and you will get a straight answer. More on the security page, or write to hello@sandsai.co.